dc dotCreds
CompTIA SecAI+ Practice Test

CompTIA SecAI+ Practice Test

Start today’s free 10-question CompTIA SecAI+ set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 31, 2026, 10:48 PM CDT

Go Pro - One Time Unlock

Unlock the full CompTIA SecAI+ CY0-001 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 CompTIA SecAI+ questions

Use this CompTIA SecAI+ practice test to review CompTIA SecAI+ CY0-001. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective 3.2 Explain how AI enables or enhances attack vectors. Domain 3: AI-assisted Security (24%)

Malware operators use a model to repeatedly rewrite scripts so each version has different variable names, control flow, and surface syntax while preserving malicious behavior. What is AI enhancing?

Concept tested:
Question 2 of 10
Objective 3.3 Given a scenario, use AI to automate security tasks. Domain 3: AI-assisted Security (24%)

An AI system notices that a newly deployed detection rule sharply increases false positives and recommends reverting to the prior version. What is the BEST automation design?

Concept tested:
Question 3 of 10
Objective 3.3 Given a scenario, use AI to automate security tasks. Domain 3: AI-assisted Security (24%)

After a major incident, responders have validated timelines, evidence tables, and action items. Which AI automation use is appropriate for preparing a first draft of the lessons-learned document?

Concept tested:
Question 4 of 10
Objective 3.2 Explain how AI enables or enhances attack vectors. Domain 3: AI-assisted Security (24%)

A botnet operator uses AI to adapt request patterns in real time, shifting targets and timing to maximize resource exhaustion while avoiding simple thresholds. Which attack vector is being enhanced?

Concept tested:
Question 5 of 10
Objective 1.1 Compare and contrast various AI types and techniques used in cybersecurity. Domain 1: Basic AI Concepts Related to Cybersecurity (17%)

An edge security appliance must run an existing neural model with less memory and compute. The team wants to remove low-impact parameters while preserving as much accuracy as practical. Which technique should it evaluate?

Concept tested:
Question 6 of 10
Objective 3.1 Given a scenario, use AI-enabled tools to facilitate security tasks. Domain 3: AI-assisted Security (24%)

A SOC wants analysts to ask natural-language questions such as “Summarize the last hour of critical alerts and cite the underlying events.” Which tool interface is MOST directly suited to the interaction?

Concept tested:
Question 7 of 10
Objective 1.3 Explain the importance of security throughout the life cycle of AI. Domain 1: Basic AI Concepts Related to Cybersecurity (17%)

A model passed laboratory tests, but before production traffic is enabled the team verifies endpoint authentication, logging, guardrails, model version, and rollback procedures in the actual environment. What is the PRIMARY purpose of this step?

Concept tested:
Question 8 of 10
Objective 4.3 Summarize the impact of compliance on business use and development of AI. Domain 4: AI Governance, Risk, and Compliance (19%)

A multinational wants nonbinding international guidance emphasizing trustworthy AI, human rights and democratic values, transparency, robustness, and accountability. Which source BEST matches?

Concept tested:
Question 9 of 10
Objective 2.6 Given a scenario, analyze the evidence of an attack and suggest compensating controls for AI systems. Domain 2: Securing AI Systems (40%)

An attacker compares a model's responses and confidence values for a particular person's record against other samples to determine whether that record was part of training. Which attack is this?

Concept tested:
Question 10 of 10
Objective 1.2 Explain the importance of data security in relation to AI. Domain 1: Basic AI Concepts Related to Cybersecurity (17%)

A security classifier is trained on 99.7% benign events and 0.3% confirmed malicious events. It achieves high overall accuracy but rarely detects attacks. Which dataset action is MOST directly intended to address this class imbalance?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
CompTIA SecAI+ CY0-001 Pro $4.99 one-time

Unlock all 200 CompTIA SecAI+ questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question CompTIA SecAI+ CY0-001 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full CompTIA SecAI+ CY0-001 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily CompTIA SecAI+ CY0-001 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily CompTIA SecAI+ set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 Malware operators use a model to repeatedly rewrite scripts so each version has different variable names, control flow, and surface syntax while preserving malicious behavior. What is AI enhancing?

Answer choices

  1. A. AI-assisted obfuscation that changes surface form while preserving behavior
  2. B. Automated attack generation that creates new payloads or malware capabilities from requirements
  3. C. AI-assisted social engineering that personalizes persuasive messages for selected victims
  4. D. AI-assisted reconnaissance that gathers and prioritizes information about potential targets

Correct answer

AI-assisted obfuscation that changes surface form while preserving behavior

Obfuscation changes how malicious code appears while retaining its underlying function, helping variants evade straightforward detection. Choice B is not best because attack generation creates attack artifacts, but the described repeated rewriting specifically preserves behavior while altering appearance. Choice C is not best because social engineering manipulates people rather than mutating malware representation. Choice D is not best because reconnaissance gathers target information and does not describe code mutation.

Wrong-answer review

  • B. Automated attack generation that creates new payloads or malware capabilities from requirements: Attack generation creates attack artifacts, but the described repeated rewriting specifically preserves behavior while altering appearance.
  • C. AI-assisted social engineering that personalizes persuasive messages for selected victims: Social engineering manipulates people rather than mutating malware representation.
  • D. AI-assisted reconnaissance that gathers and prioritizes information about potential targets: Reconnaissance gathers target information and does not describe code mutation.

Extra learning features

Why candidates miss this

**Correct concept: Obfuscation.** The malicious behavior stays the same while names, control flow, and syntax change to alter the surface representation. Automated attack generation would create or discover new payloads/capabilities rather than merely re-express existing code. The tempting answer, “Automated attack generation that creates new payloads or malware capabilities from requirements,” misses the specific mechanism tested by the stem. Likely wrong answer: Automated attack generation that creates new payloads or malware capabilities from requirements Review focus: CompTIA SecAI+ CY0-001 V1 Certification Exam Objectives v1.1

Interview question

Q: What is the difference between AI-assisted malware obfuscation and AI-generated attack creation? Strong answer: Obfuscation changes the representation of existing malicious code—such as names, control flow, or syntax—while preserving its behavior to evade detection. Automated attack generation creates or discovers new attack artifacts, payloads, or techniques from requirements. The key clue for obfuscation is changed surface form with preserved function.

  • surface form changes
  • behavior preserved
  • evasion
  • new payload generation is different

Caution: Look for applied reasoning and tradeoffs, not a one-word term or a restatement of the multiple-choice item.

Objective/domain: Domain 3: AI-assisted Security (24%)

Source: CompTIA SecAI+ CY0-001 V1 Certification Exam Objectives v1.1

Question 2 An AI system notices that a newly deployed detection rule sharply increases false positives and recommends reverting to the prior version. What is the BEST automation design?

Answer choices

  1. A. Allow automated rollback only under approved thresholds and change controls, with full logging.
  2. B. Require a human to execute every rollback manually after the AI recommends it, even when preapproved thresholds are met.
  3. C. Use AI-assisted change approval before deployment but provide no automated rollback path after release.
  4. D. Permit the AI agent to rewrite and redeploy any detection rule whenever it predicts lower false-positive rates.

Correct answer

Allow automated rollback only under approved thresholds and change controls, with full logging.

Objective/domain: Domain 3: AI-assisted Security (24%)

Source: CompTIA SecAI+ CY0-001 V1 Certification Exam Objectives v1.1

Question 3 After a major incident, responders have validated timelines, evidence tables, and action items. Which AI automation use is appropriate for preparing a first draft of the lessons-learned document?

Answer choices

  1. A. Ask the model to invent missing evidence so the report is complete.
  2. B. Automatically delete the underlying evidence after summarization.
  3. C. Synthesize and summarize the validated incident material, then require human review.
  4. D. Treat the generated draft as final without verification.

Correct answer

Synthesize and summarize the validated incident material, then require human review.

Objective/domain: Domain 3: AI-assisted Security (24%)

Source: CompTIA SecAI+ CY0-001 V1 Certification Exam Objectives v1.1

Question 4 A botnet operator uses AI to adapt request patterns in real time, shifting targets and timing to maximize resource exhaustion while avoiding simple thresholds. Which attack vector is being enhanced?

Answer choices

  1. A. Model inversion
  2. B. Apply provenance watermarks to generated content so recipients can identify AI-produced material
  3. C. Distributed denial-of-service (DDoS)
  4. D. Code linting

Correct answer

Distributed denial-of-service (DDoS)

Objective/domain: Domain 3: AI-assisted Security (24%)

Source: CompTIA SecAI+ CY0-001 V1 Certification Exam Objectives v1.1

Question 5 An edge security appliance must run an existing neural model with less memory and compute. The team wants to remove low-impact parameters while preserving as much accuracy as practical. Which technique should it evaluate?

Answer choices

  1. A. Data balancing to change class representation in the training dataset
  2. B. Multi-shot prompting with several worked examples in the prompt
  3. C. Pruning low-impact model parameters to reduce resource use
  4. D. Model validation against a representative holdout or test dataset

Correct answer

Pruning low-impact model parameters to reduce resource use

Objective/domain: Domain 1: Basic AI Concepts Related to Cybersecurity (17%)

Source: CompTIA SecAI+ CY0-001 V1 Certification Exam Objectives v1.1

Question 6 A SOC wants analysts to ask natural-language questions such as “Summarize the last hour of critical alerts and cite the underlying events.” Which tool interface is MOST directly suited to the interaction?

Answer choices

  1. A. Provide analysts a raw model artifact and require them to build their own interaction interface
  2. B. An approved security chatbot connected to authorized data sources
  3. C. A static firewall rule list
  4. D. An offline checksum utility

Correct answer

An approved security chatbot connected to authorized data sources

Objective/domain: Domain 3: AI-assisted Security (24%)

Source: CompTIA SecAI+ CY0-001 V1 Certification Exam Objectives v1.1

Question 7 A model passed laboratory tests, but before production traffic is enabled the team verifies endpoint authentication, logging, guardrails, model version, and rollback procedures in the actual environment. What is the PRIMARY purpose of this step?

Answer choices

  1. A. Retrain the model on the production request stream before controls are checked.
  2. B. Eliminate the need for post-deployment monitoring.
  3. C. Replace data lineage records with deployment logs.
  4. D. Validate that the deployed implementation matches approved security and operational requirements.

Correct answer

Validate that the deployed implementation matches approved security and operational requirements.

Objective/domain: Domain 1: Basic AI Concepts Related to Cybersecurity (17%)

Source: CompTIA SecAI+ CY0-001 V1 Certification Exam Objectives v1.1

Question 8 A multinational wants nonbinding international guidance emphasizing trustworthy AI, human rights and democratic values, transparency, robustness, and accountability. Which source BEST matches?

Answer choices

  1. A. The European Union Artificial Intelligence Act, a binding legal framework applying to covered AI uses in the EU
  2. B. ISO/IEC 42001:2023, an international standard for an organizational AI management system
  3. C. OECD AI Principles
  4. D. The NIST AI Risk Management Framework, a voluntary framework for managing AI risk and trustworthiness

Correct answer

OECD AI Principles

Objective/domain: Domain 4: AI Governance, Risk, and Compliance (19%)

Source: OECD AI Principles

Question 9 An attacker compares a model's responses and confidence values for a particular person's record against other samples to determine whether that record was part of training. Which attack is this?

Answer choices

  1. A. Model theft
  2. B. Jailbreaking
  3. C. Use data poisoning to modify training examples and influence future model behavior
  4. D. Membership inference

Correct answer

Membership inference

Objective/domain: Domain 2: Securing AI Systems (40%)

Source: CompTIA SecAI+ CY0-001 V1 Certification Exam Objectives v1.1

Question 10 A security classifier is trained on 99.7% benign events and 0.3% confirmed malicious events. It achieves high overall accuracy but rarely detects attacks. Which dataset action is MOST directly intended to address this class imbalance?

Answer choices

  1. A. Rebalance the training data so minority attack examples receive appropriate representation.
  2. B. Increase prompt token limits so each analyst query can include more historical event context
  3. C. Encrypt the model weights at rest.
  4. D. Replace the validation set with the training set.

Correct answer

Rebalance the training data so minority attack examples receive appropriate representation.

Objective/domain: Domain 1: Basic AI Concepts Related to Cybersecurity (17%)

Source: CompTIA SecAI+ CY0-001 V1 Certification Exam Objectives v1.1

Where to go after the daily web set

How are CompTIA SecAI+ questions generated?

dotCreds builds CompTIA SecAI+ practice questions from public exam objectives and CompTIA exam objectives and source-backed references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start CompTIA SecAI+ practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.